Deepak GhengatI'm a _
I break web apps, mobile apps, APIs and networks — then document exactly how to fix them.
About me
Offensive security practitioner with a decade of hands-on vulnerability research. I specialise in end-to-end assessments across web applications, mobile (Android & iOS), REST/GraphQL APIs, network infrastructure and thick-client software. I've reported 100+ verified vulnerabilities across public and private bug bounty programs, built open-source offensive tooling used by other testers, and published original research on GraphQL batching attacks.
My focus is depth over breadth on a target: I map the full attack surface, chain low-severity issues into real impact, and always ship a reproduction-ready proof of concept so engineering teams can fix fast. I work equally across web, mobile, API and network layers, and I build my own tooling when the off-the-shelf scanners fall short.
“The true value of ethical hacking lies in its ability to provide a fresh perspective and find the weaknesses that others may have missed.”
Vulnerability classes I report
- Base
- Pune, Maharashtra, India
- Model
- Remote · full-time & engagements
- Focus
- Web · Mobile · API · Network
- Since
- Researching since 2014
What I test
Web Application Security
Full-scope testing of modern web apps — authentication, access control and business-logic flaws that scanners never find.
- OWASP Top 10 & beyond
- Authentication / session bypass
- IDOR & broken access control
- SSRF · XSS · CSRF
- SQL & command injection
- Business-logic exploitation
API & GraphQL Security
REST and GraphQL assessments including rate-limit bypass, batching abuse and authorization gaps at the API layer.
- REST & GraphQL testing
- GraphQL batching / DoS
- Broken object-level auth (BOLA)
- Mass assignment
- Rate-limit & lockout bypass
- Token & JWT abuse
Mobile Application Security
Android and iOS assessments covering static, dynamic and network-layer analysis of the mobile attack surface.
- Android (APK) analysis
- iOS (IPA) analysis
- Static & dynamic testing
- Insecure storage & IPC
- ADB & runtime tooling
- Traffic interception / SSL pinning
Network Penetration Testing
Internal and external network assessments — from discovery and enumeration to exploitation and privilege escalation.
- External & internal pentest
- Service enumeration
- Vulnerability assessment
- Exploitation & pivoting
- Misconfiguration review
- Network segmentation checks
Thick-Client & Systems
Desktop / thick-client application testing and OS-level security research across Windows and Linux.
- Thick-client app testing
- Local privilege escalation
- Binary & config review
- Windows / Linux internals
- Reverse engineering basics
- Directory traversal / LFI
Red Teaming & OSINT
Adversary-simulation mindset backed by reconnaissance and open-source intelligence to map the real attack surface.
- Recon & asset discovery
- OSINT gathering
- Attack-surface mapping
- PoC & exploit development
- Custom Python/Bash automation
- Responsible disclosure
Bug bounty & disclosure
Continuous vulnerability research since 2014 across public and private programs. 100+ verified reports with a 100% acceptance rate, spanning web, mobile, API and network targets — and Hall of Fame recognition from multiple vendors.
Zoho
Critical & high-severity web/API findings
TripAdvisor
Authentication & business-logic flaws
Adafruit
Web application vulnerabilities
Intel
Vulnerability reporting acknowledgment
Bugcrowd
Verified submissions on managed programs
Intigriti
European crowdsourced program findings
Experience
Cyber Security Consultant & Security Engineer
Tigres Global
- Led penetration tests across web dashboards, REST & GraphQL APIs, auth flows and server-side infrastructure.
- Uncovered 15+ critical and high-severity vulnerabilities and drove clean-audit remediation within 30 days.
- Built custom Python & Bash automation for recon and exploit verification, cutting manual effort ~60%.
- Delivered comprehensive reports with CVSS scoring and prioritised remediation guidance.
Junior Security Engineer
Lumiverse InfoSolutions
- Conducted security audits and penetration tests across web applications and corporate networks.
- Automated OWASP Top 10 detection with custom Python tooling, reducing testing time ~35%.
- Supported secure-configuration and hardening rollouts across client infrastructure.
Independent Bug Bounty Researcher
Bugcrowd · Intigriti · HackerOne · Private Programs
- Reported 100+ verified vulnerabilities across web, mobile and API targets with a 100% acceptance rate.
- Earned Hall of Fame recognition from Zoho, TripAdvisor, Adafruit and acknowledgment from Intel.
- Developed reproduction-ready proof-of-concept exploits that accelerated vendor remediation.
- Published open-source offensive tooling used by the wider testing community.
Tools & research
Writing & certifications
Certifications
- Certified Penetration Testing Engineer (CPTE)2018CRISIL
- Certified Information Security Professional (CISP)2017CRISIL
- Cybersecurity CertificationCertiProf
- Vulnerability Reporting AcknowledgmentIntel